- NYT v. OpenAI unsealed: the 'theft' memo
+ Astra for Law: 54% on the legal bench
- ZCode uploads your .git; Z.ai keeps the key
- OpenAI repos breached; bounty $6,500In January 2023, a Microsoft director wrote a memo calling what his own company was doing the largest theft of labor in human history, and yesterday a federal court let the rest of us read it. The memo is one of the unredacted quotes in New York Times versus OpenAI and Microsoft, a lawsuit that turns three this December. The same Thursday, OpenAI shipped Astra for Law, a model for lawyers, which is either a coincidence or a very strong hire. This morning a developer caught ZCode, Z dot A I's coding agent, uploading his entire git history to Alibaba's cloud with a key only Z dot A I holds. And a security firm walked into OpenAI's internal repositories through an image upload, for which OpenAI paid six thousand five hundred dollars. Start with the memo. Brent Hecht runs applied science at Microsoft, and in January 2023 he called the training data an astonishing theft of unprecedented proportions. A year later he was back with a slide deck: Copilot's answer engine cut click-throughs to the Times by up to ninety-three percent, which he named a doom loop: starve the publishers, and the model has nothing new to eat. His words: an end product that threatens the economic foundations of its essential suppliers, the corporate way of saying the snake has located its tail.
Then the depositions. Satya Nadella testified this year that anything paywalled should be licensed, and that had he known OpenAI trained on paywalled articles he would have made them retrain, which assumes nobody at Microsoft opened the training set they were handed, and per the same filing that was the entire GPT-3 dataset. Nick Turley, who runs ChatGPT, called it an existential threat to publishers, largely substitutive. And when a researcher told Greg Brockman about a hack to get around the Times paywall, the president of OpenAI replied with two words: ah nice. Engineers also stripped copyright notices out of the data so the model wouldn't output them, which is why you file the serial number off a bicycle. The scale: more than ninety-one thousand copies of the plaintiffs' articles in the mid-training sets alone, and two million Times pages in one Common Crawl slice. Now the part the headline skips. Every quote comes from the Times' brief; the exhibits are still sealed, so we are reading the prosecution's highlights without context. And courts have mostly sided with fair use: Judge Alsup ruled last year that training on books you paid for is legal, though Anthropic still paid one and a half billion for the seven million it pirated. So the legal question is open. Whether the people building it thought it was theft is, as of yesterday, not. Which makes Thursday's other OpenAI launch a bold choice. Astra for Law wraps GPT-6 Astra, the model I stamped REVERT last week after it produced seventy-five thousand lines of nothing, in a legal search index of two hundred and thirty million pages. On Vals AI's legal research benchmark it passes fifty-four percent of questions, up from thirty-nine with plain web search, which OpenAI calls a forty percent improvement and a lawyer would call wrong nearly half the time. The blog post does not contain the word hallucination. Hacker News did: will it be able to sue itself, which, given the week, is the first genuine use case.
Meanwhile the theft-of-labor discourse reached your laptop. A developer called ferstar cleaned out his ZCode folder, Z dot A I's closed desktop agent for the GLM models, and found a three hundred and thirteen megabyte encrypted archive of his commercial workspace: forty-two thousand files, eighty-seven percent of it the dot git directory, shipped to Alibaba's object storage on login and before every prompt. The archive is wrapped with a public key the server hands out; the private key lives only in Z dot A I's cloud, so the ciphertext on your own disk is unreadable to you. His line: a key that only the server can use serves exactly one purpose. Z dot A I is also the company Anthropic accused of distilling Claude, so the weights are open and so, apparently, is your repo. And the funny one, unless you work at OpenAI. Hacktron found a heap overflow in libheif, uploaded a crafted picture to community dot openai dot com, got code execution on the forum, and rode a misconfigured single sign-on through the GitHub integration into OpenAI's internal repositories, in under seventy-two hours. The exploit was written by Claude: Opus 4.8 could not beat address randomisation, Opus 5 did it within three hours of release. The whole campaign cost under three thousand dollars in tokens. OpenAI patched in fourteen hours and paid six thousand five hundred dollars, so the source code of a trillion-dollar company was, briefly, priced like a used Corolla, on the same day its lawyers argued that copying is fair use.
Verdict: NEEDS REVIEW — Real quotes, sealed exhibits: the memo settled the ethics, not the law.
Sources
https://techcrunch.com/2026/09/17/microsoft-exec-called-ai-scraping-the-largest-theft-of-labor-in-human-history-new-unredacted-filings-reveal/
https://news.ycombinator.com/item?id=49752056
https://en.wikipedia.org/wiki/Anthropic#Legal_issues
https://x.com/jason_kint/status/2100611139906228629
https://x.com/ednewtonrex/status/2100649215290466631
https://x.com/arstechnica/status/2100679975196397596
https://openai.com/index/astra-for-law/
https://news.ycombinator.com/item?id=49745940
https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot/
https://tokenstead.ai/guides/zcode-silent-git-history-upload
https://news.ycombinator.com/item?id=49752422
https://x.com/ferstar_org/status/2100805861002355154
https://x.com/Fei2411/status/2100847306203599047
https://www.hacktron.ai/blog/hacking-openai
https://news.ycombinator.com/item?id=49749656
And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
YouTube · thedailydiff.dev · forward this to the intern who deployed on Friday.

